Re: Identifying Windows O/S & SP

From: Roger Dodger (random_alphanumeric_characters_at_yahoo.com)
Date: 08/25/05

  • Next message: Mark Sec: "Software Proxys Anonymous"
    Date: Wed, 24 Aug 2005 22:18:21 -0700 (PDT)
    To: pen-test@securityfocus.com
    
    

    How about trusty ol'Nmap

    nmap -P0 -O -T Paranoid <ip address>

    I didn't do a packet count but should avoid IDS in
    paranoid mode...

    Cheers,
    RAC

    ----Original Message-----
    From: L3wD [mailto:l3wd@earthlink.net]
    Sent: Wednesday, August 24, 2005 6:53 PM
    To: pen-test@securityfocus.com
    Subject: Identifying Windows O/S & SP

        I am looking for a method of correctly identifying
    Windows O/S
    Versions and Service Packs remotely. Here are my
    restrictions:
    - Performed Remotely (not in same broadcast domain)
    - No Admin Rights on Remote Box
    - No Username/Password on Remote Box
    - VERY Few Packets Generated (excluding TCP 3-way
    handshake)
    - Ability to **AVOID** IDS Detection

        My preferences are for something that is command
    line based, and can
    be run from a Linux platform. I'll take something GUI
    based or Windows
    based if that is all there is. Multiple tools are
    fine, as long as the
    number of packets generated are very low.

        I've taken a look at Winfingerprint 0.6.2 with
    only the Win32 OS
    Version option selected, but it generates 70+ packets
    which is too loud
    for my purposes.

    __________________________________________________
    Do You Yahoo!?
    Tired of spam? Yahoo! Mail has the best spam protection around
    http://mail.yahoo.com


  • Next message: Mark Sec: "Software Proxys Anonymous"

    Relevant Pages

    • Re: What is going on with my Dialup?
      ... also forward it to an unused port, and have that port provide the ... verses the RST or ICMP 3,3. ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
      (comp.os.linux.networking)
    • Re: What is going on with my Dialup?
      ... also forward it to an unused port, and have that port provide the ... There is a huge debate of whether it's better to provide no response ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
      (comp.os.linux.networking)
    • Re: After many hours all outbound connections get stuck in SYN_SENT
      ... Back to your SYN_SENT problem, I suppose the remote IP is known, so you ... I've run tcpdump for all IPs during this problem. ... tcpdump reported that some packets were dropped during the capture. ...
      (Linux-Kernel)
    • Re: After many hours all outbound connections get stuck in SYN_SENT
      ... Back to your SYN_SENT problem, I suppose the remote IP is known, so you ... I've run tcpdump for all IPs during this problem. ... tcpdump reported that some packets were dropped during the capture. ...
      (Linux-Kernel)
    • Re: After many hours all outbound connections get stuck in SYN_SENT
      ... Back to your SYN_SENT problem, I suppose the remote IP is known, so you ... I've run tcpdump for all IPs during this problem. ... tcpdump reported that some packets were dropped during the capture. ...
      (Linux-Kernel)